Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-10198


Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).


Published

2017-08-08T15:29:05.837

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle jdk 1.6.0 Yes
Application oracle jdk 1.7.0 Yes
Application oracle jdk 1.8.0 Yes
Application oracle jre 1.6.0 Yes
Application oracle jre 1.7.0 Yes
Application oracle jre 1.8.0 Yes
Application oracle jrockit r28.3.14 Yes
Application phoenixcontact fl_mguard_dm ≤ 1.8.0 Yes
Operating System debian debian_linux 8.0 Yes
Operating System debian debian_linux 9.0 Yes
Application netapp active_iq_unified_manager ≥ 7.3 Yes
Application netapp active_iq_unified_manager ≥ 9.5 Yes
Application netapp cloud_backup - Yes
Application netapp e-series_santricity_os_controller ≤ 11.70.1 Yes
Application netapp e-series_santricity_storage_manager - Yes
Application netapp element_software - Yes
Application netapp oncommand_balance - Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_performance_manager - Yes
Application netapp oncommand_shift - Yes
Application netapp oncommand_unified_manager ≤ 7.1 Yes
Application netapp oncommand_unified_manager ≤ 7.1 Yes
Application netapp oncommand_unified_manager - Yes
Application netapp plug-in_for_symantec_netbackup - Yes
Application netapp snapmanager - Yes
Application netapp snapmanager - Yes
Application netapp steelstore_cloud_integrated_storage - Yes
Application netapp storage_replication_adapter_for_clustered_data_ontap ≥ 7.2 Yes
Application netapp storage_replication_adapter_for_clustered_data_ontap 9.6 Yes
Application netapp vasa_provider_for_clustered_data_ontap ≥ 7.2 Yes
Application netapp vasa_provider_for_clustered_data_ontap 6.0 Yes
Application netapp virtual_storage_console ≥ 7.2 Yes
Application netapp virtual_storage_console - Yes
Application netapp virtual_storage_console 6.0 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_eus 7.3 Yes
Operating System redhat enterprise_linux_eus 7.4 Yes
Operating System redhat enterprise_linux_eus 7.5 Yes
Operating System redhat enterprise_linux_eus 7.6 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.4 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes

References